CVE-2024-43446

LOW

OTRS 7.0.x-8.0.x, 2023.x-2024.x & Community Edition 6.0.x - Privilege Escalation in Generic Interface

Title source: llm
STIX 2.1

Description

An improper privilege management vulnerability in OTRS Generic Interface module allows change of the Ticket status even if the user only has ro permissions. This issue affects: * OTRS 7.0.X * OTRS 8.0.X * OTRS 2023.X * OTRS 2024.X * ((OTRS)) Community Edition: 6.0.x Products based on the ((OTRS)) Community Edition also very likely to be affected

References (1)

Core 1

Scores

CVSS v3 3.5
EPSS 0.0020
EPSS Percentile 9.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-269
Status published
Products (6)
OTRS AG/((OTRS)) Community Edition 6.0.x - 6.0.34
OTRS AG/OTRS 2023.x
OTRS AG/OTRS 2024.x
OTRS AG/OTRS 2025.x - 2025.1.x
OTRS AG/OTRS 7.0.x
OTRS AG/OTRS 8.0.x
Published Jan 27, 2025
Tracked Since Feb 18, 2026